CVE-2021-38648

O

pen Management Infrastructure Elevation of Privilege Vulnerability

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microsoft:azure_automation_state_configuration:-:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:azure_automation_update_management:-:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:azure_diagnostics_\(lad\):-:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:azure_open_management_infrastructure:-:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:azure_security_center:-:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:azure_sentinel:-:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:azure_stack_hub:-:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:container_monitoring_solution:-:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:log_analytics_agent:-:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:system_center_operations_manager:-:*:*:*:*:*:*:*

History

30 Oct 2025, 19:13

Type Values Removed Values Added
References () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-38648 - () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-38648 - US Government Resource

22 Oct 2025, 00:17

Type Values Removed Values Added
References
  • () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-38648 -

21 Oct 2025, 20:18

Type Values Removed Values Added
References
  • {'url': 'https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-38648', 'source': '134c704f-9b21-4f2e-91b3-4a467353bcc0'}

21 Oct 2025, 19:19

Type Values Removed Values Added
References
  • () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-38648 -

07 Mar 2025, 21:58

Type Values Removed Values Added
CWE CWE-287 NVD-CWE-noinfo

21 Nov 2024, 06:17

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/164925/Microsoft-OMI-Management-Interface-Authentication-Bypass.html - Exploit, Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/164925/Microsoft-OMI-Management-Interface-Authentication-Bypass.html - Exploit, Third Party Advisory, VDB Entry
References () https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-38648 - Patch, Vendor Advisory () https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-38648 - Patch, Vendor Advisory